LastPass has reported a security incident where an unauthorized party gained access to a cloud-based storage environment, obtaining backups of customer vault data, including unencrypted website URLs and encrypted sensitive fields. The encrypted fields remain secured with 256-bit AES encryption and can only be decrypted with a unique encryption key derived from each user's master password. The company has notified law enforcement and relevant regulatory authorities and is taking measures to enhance security. Customers are advised to follow best practices and consider changing passwords as a precaution.